Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mono 'EnableViewStateMac'跨站脚本攻击漏洞
Vulnerability Description
Mono是一个自由开源的项目。该项目的目标是创建一系列符合ECMA标准(Ecma-334和Ecma-335)的.NET工具,包括C#编译器和通用语言架构。 Mono所使用的默认ASP.NET配置对EnableViewStateMac属性设置了FALSE值,远程攻击者可以利用此漏洞导致跨站脚本攻击(XSS),例如通过向2.0/menu /menu1.aspx提交特制的__VIEWSTATE参数执行跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A